Chilkat HOME Android™ AutoIt C C# C++ Chilkat2-Python CkPython Classic ASP DataFlex Delphi DLL Go Java Node.js Objective-C PHP Extension Perl PowerBuilder PowerShell PureBasic Ruby SQL Server Swift Tcl Unicode C Unicode C++ VB.NET VBScript Visual Basic 6.0 Visual FoxPro Xojo Plugin
(Tcl) Working with PEM Encrypted Private KeysDemonstrates how to load and save PEM encrypted private keys.
load ./chilkat.dll # Starting in v9.5.0.49, all Chilkat classes can be unlocked at once at the beginning of a program # by calling UnlockBundle. It requires a Bundle unlock code. set chilkatGlob [new_CkGlobal] set success [CkGlobal_UnlockBundle $chilkatGlob "Anything for 30-day trial."] if {$success != 1} then { puts [CkGlobal_lastErrorText $chilkatGlob] delete_CkGlobal $chilkatGlob exit } set pem [new_CkPem] set pemPassword "secret" # To load a PEM file containing encrypted private keys, simply # provide the password. set success [CkPem_LoadPemFile $pem "/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem" $pemPassword] if {$success != 1} then { puts [CkPem_lastErrorText $pem] delete_CkGlobal $chilkatGlob delete_CkPem $pem exit } set fac [new_CkFileAccess] set pemText [CkFileAccess_readEntireTextFile $fac "/Users/chilkat/testData/pem/pemContainingEncryptedPrivateKeys.pem" $pemPassword] # To load a PEM from a string, call LoadPem instead of LoadPemFile: set success [CkPem_LoadPem $pem $pemText] if {$success != 1} then { puts [CkPem_lastErrorText $pem] delete_CkGlobal $chilkatGlob delete_CkPem $pem delete_CkFileAccess $fac exit } # A few notes: # The PEM may contain both private keys and certificates (or anything else). # The password is utilized for whatever content in the PEM is encrypted. # It is OK to have both encrypted and non-encrypted content within a given PEM. # PEM private keys can be encrypted in different formats. The LoadPem and LoadPemFile # methods automatically handle the different formats. # One format is PKCS8 and is indicated by this delimiter within the PEM: # -----BEGIN ENCRYPTED PRIVATE KEY----- # MIICoTAbBgkqhkiG9w0BBQMwDgQIfdD0zv24lgkCAggABIICgE0PdHJmRbNs6cBX # ... # Another format, we'll call "passphrase" looks like this in the PEM: # -----BEGIN RSA PRIVATE KEY----- # Proc-Type: 4,ENCRYPTED # DEK-Info: DES-EDE3-CBC,A4215544D11C5D0C # # paqy9XRexcSjurHfG0xhCaUD0HrvIdhuC0CbRxxxeMlkLaV6+uT80rBxt2AaibWG # ... # Show the bit length of each private key: set numPrivateKeys [CkPem_get_NumPrivateKeys $pem] if {$numPrivateKeys == 0} then { puts "Error: Expected the PEM to contain private keys." delete_CkGlobal $chilkatGlob delete_CkPem $pem delete_CkFileAccess $fac exit } for {set i 1} {$i <= $numPrivateKeys} {incr i} { # privKey is a CkPrivateKey set privKey [CkPem_GetPrivateKey $pem [expr $i - 1]] puts "$i: [CkPrivateKey_get_BitLength $privKey] bits" delete_CkPrivateKey $privKey } delete_CkGlobal $chilkatGlob delete_CkPem $pem delete_CkFileAccess $fac |
© 2000-2025 Chilkat Software, Inc. All Rights Reserved.